Configuring a threat feed
Threat feeds are plain text files that contain a list of security threats. Threat feeds can be hosted on FortiClient EMS, third party servers, or your own HTTP/HTTPS web server. In this way, FortiMail units can utilize security information from many vendors, security communities, and specialist teams in your own organization. Once FortiMail is connected to threat feeds, you can select them when you configure security features such as antivirus file signatures and antispam IP reputation and URL filters.
FortiMail periodically synchronizes with threat feeds and automatically imports changes.
If the threat feed's web server becomes unreachable and there is a connection status error, then the FortiMail continues to use its existing local cache of the threat feed, regardless of reboot. To get threat feed updates, you must re-establish network connectivity. |
The maximum number of threat feeds varies by model. See Appendix B: Maximum Values.
To configure a threat feed
-
Go to Security > Threat Feed > Threat Feed.
-
Either click New to add a threat feed or double-click an existing one to modify it.
-
Configure the following settings and then click Create.
GUI item
Description Enable or disable the threat feed.
Name Enter a unique name. Comment Optional. Enter a description or comment. Resource URL Enter the URI of the threat feed.
FortiMail also supports OASIS STIX/TAXII format. To use the TAXII protocol, use the
stix://
prefix instead ofhttps://
.Resource type Select either:
- URL Category
- IP Address
- Malware Hash
For details, see Types and file formats of threat feeds.
The automatically assigned identifier number for threats that match this FortiGuard URL filter category.
The ID cannot be changed. The field appears only when you edit an existing threat feed, and its Resource type is URL Category.
Username If the server requires authentication, enter the username that FortiMail will use to connect. Password If the server requires authentication, enter the password that FortiMail will use to connect. Server identity check Select the level of server certificate validation strictness, either:
- None — No certificate validation.
- Basic — Validate the server certificate. It must not be revoked or expired, and must be signed by a trusted CA. See also Managing certificate authority certificates.
- Full — In addition to validation requirements in Basic, the domain name in Resource URL must match the common name (CN) field in the server certificate.
To harden security, select Full.
Update interval Enter the frequency in minutes of synchronization with the threat feed. Default value is 30 minutes. Valid range is from 1 to 43200 minutes (30 days).
-
To apply the threat feed, select it in an antivirus file signature, custom URL category or override, or antispam profile. See Configuring file signatures, Configuring custom URL rating categories, and FortiGuard section.